workflow-metrics
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines a quantitative scoring system for creative projects. Its instructions are purely logical and do not contain prompt injection attempts or efforts to bypass safety guardrails.
- [DATA_EXFILTRATION]: The skill reads project state files (
project_state.jsonanddecision_log.md) to extract metrics. These operations are limited to the local environment, and no network tools (like curl or wget) or external domains are referenced in the instructions. - [COMMAND_EXECUTION]: The skill specifies scoring logic in pseudo-code (Python/JSON format), but these are provided as instructions for the agent to follow rather than executable shell scripts. No risky subprocess or system-level commands were detected.
- [REMOTE_CODE_EXECUTION]: There are no external dependencies, package installations, or remote script fetches. The skill is entirely self-contained within the provided instructions.
Audit Metadata